> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Product compliance panel for the embeddable PIP widget

> Public, unauthenticated read powering `/widget/v1/pip-panel.js`. Returns recall status, allergens, certifications and the printed ingredient label for one GTIN, reduced to the disclosure level the hosted page would serve an anonymous visitor.



## OpenAPI

````yaml /openapi/openapi-products.json get /products/api/v1/public/pip/{gtin}
openapi: 3.1.0
info:
  title: Products API
  version: 1.0.0
  description: >
    Look up, claim, and browse GTINs in the Closient product repository.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
tags:
  - name: Products
    description: Look up, claim, and browse products and trade items.
  - name: Product Group
    description: Manage GDSN packaging hierarchy relationships.
  - name: Import
    description: >-
      Bulk import products, batch/lots (GS1 AI 10) and serial numbers (GS1 AI
      21) from CSV, TSV or XLSX files, with a downloadable template per entity.
  - name: QR
    description: Generate QR codes encoding GS1 Digital Link URLs.
  - name: Codes
    description: Generate GS1 DataMatrix and 1D barcodes (EAN/UPC/ITF-14/Code128).
  - name: Digital Link
    description: >-
      Parse GS1 Digital Link URIs into structured AIs (GTIN, lot, expiry,
      serial).
  - name: Labels
    description: >-
      Bulk label-export jobs: ZIPs of QR / DataMatrix / 1D symbols and multi-up
      sheet PDFs, async via Celery with status polling.
  - name: Lots
    description: >-
      Lot generator v2: format templates with persistent counters,
      reserve/commit/discard runs, soft/hard collision handling, and an async
      Celery path with SSE progress.
  - name: Retailer Catalog Import
    description: >-
      Server-side retailer catalog import jobs: stage normalised rows, then run
      the GTIN-keyed cross-retailer merge with a dry-run mode, per-field
      provenance and a quarantine report for every row refused.
  - name: HRI Presets
    description: >-
      Saved, named per-organisation Human Readable Interpretation (HRI)
      configurations — placement, layout, notation and typography. Referenceable
      by name from the QR generation endpoint, with an org default applied when
      no options or preset are supplied.
  - name: PIP Embed (Public)
    description: >-
      Unauthenticated, cross-origin read powering the embeddable PIP panel
      (`/widget/v1/pip-panel.js`) that retailers drop into their own product
      detail pages. Reduced to the disclosure level the hosted page would serve
      an anonymous visitor.
  - name: Product Links
    description: >-
      Generic, GS1-link-type-keyed brand CTA links (e.g. reviews, promotions,
      loyalty programs, homepage) attached to a product or a brand and rendered
      on the hosted page.
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /products/api/v1/public/pip/{gtin}:
    get:
      tags:
        - PIP Embed (Public)
      summary: Product compliance panel for the embeddable PIP widget
      description: >-
        Public, unauthenticated read powering `/widget/v1/pip-panel.js`. Returns
        recall status, allergens, certifications and the printed ingredient
        label for one GTIN, reduced to the disclosure level the hosted page
        would serve an anonymous visitor.
      operationId: apps_products_api_public_embed_get_embed_panel
      parameters:
        - in: path
          name: gtin
          schema:
            description: >-
              Product barcode. GTIN-8, 12, 13 or 14, with or without separators
              — normalized to GTIN-14 server-side, so a retailer can pass
              whatever their PIM holds.
            title: Gtin
            type: string
          required: true
          description: >-
            Product barcode. GTIN-8, 12, 13 or 14, with or without separators —
            normalized to GTIN-14 server-side, so a retailer can pass whatever
            their PIM holds.
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EmbedPanelOut'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '405':
          description: Method Not Allowed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '422':
          description: Unprocessable Content
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '429':
          description: Too Many Requests
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
components:
  schemas:
    EmbedPanelOut:
      description: >-
        Everything the embeddable panel renders for one GTIN.


        Which fields are populated depends on ``disclosure`` — read that first.

        An empty ``certifications`` on a ``full`` response means the product has

        none; on an ``unverified`` response it means Closient will not assert

        them. The two are different facts and the field alone cannot tell them

        apart, which is why ``disclosure`` is part of the contract rather than
        an

        implementation detail.
      examples:
        - allergen_warnings: May contain tree nuts.
          allergens:
            - detail: Legume allergen
              label: Peanuts
          brand_name: Example Foods
          certifications:
            - detail: Oregon Tilth
              label: USDA Organic
          disclaimers: []
          disclosure: full
          gtin: '00614141000036'
          image_url: https://media.example.com/media/products/peanut-butter.jpg
          ingredients: Roasted peanuts, salt.
          name: Creamy Peanut Butter 12oz
          pip_url: /pip/00614141000036/
          recall:
            count: 0
            headline: ''
            is_active: false
            severity_label: ''
          requires_age_verification: false
        - allergen_warnings: ''
          allergens: []
          brand_name: ''
          certifications: []
          disclaimers: []
          disclosure: unverified
          gtin: '00012345678905'
          image_url: ''
          ingredients: ''
          name: ''
          pip_url: /pip/00012345678905/
          recall:
            count: 1
            headline: Undeclared milk in 12oz jars
            is_active: true
            severity_label: Serious Health Risk
          requires_age_verification: false
      properties:
        gtin:
          description: GTIN-14, zero-padded.
          title: Gtin
          type: string
        disclosure:
          $ref: '#/components/schemas/EmbedDisclosureEnum'
          description: >-
            How much of the record this response carries. `full` is the complete
            panel. `suspended` is the safety floor for a product whose owning
            organization is in its deletion grace window. `unverified` is the
            identity floor for a GTIN whose claim is not authoritative — recall
            status only, no name. `age_restricted` withholds detail that cannot
            be age-gated on a third-party page.
        recall:
          $ref: '#/components/schemas/EmbedRecallOut'
          description: >-
            Active-recall summary. Present at every disclosure level — a recall
            is regulator-issued rather than brand-supplied, so it is never
            withheld.
        name:
          default: ''
          description: Product name. Always empty on an `unverified` response.
          title: Name
          type: string
        brand_name:
          default: ''
          description: Brand name. Empty unless `disclosure` is `full`.
          title: Brand Name
          type: string
        image_url:
          default: ''
          description: Product image URL. Empty when there is no usable image.
          title: Image Url
          type: string
        allergens:
          description: Declared allergen traits.
          items:
            $ref: '#/components/schemas/EmbedFactOut'
          title: Allergens
          type: array
        certifications:
          description: Assigned certifications.
          items:
            $ref: '#/components/schemas/EmbedFactOut'
          title: Certifications
          type: array
        ingredients:
          default: ''
          description: The printed ingredient label, verbatim.
          title: Ingredients
          type: string
        allergen_warnings:
          default: ''
          description: '''May contain'' / cross-contamination warnings.'
          title: Allergen Warnings
          type: string
        requires_age_verification:
          default: false
          description: >-
            True when the full record is only available behind the hosted page's
            18+ gate.
          title: Requires Age Verification
          type: boolean
        disclaimers:
          description: >-
            Legal disclaimer paragraphs required for this product's regulatory
            regime (e.g. DSCSA pharma). Empty for an unregulated product. **When
            non-empty these must be displayed alongside the panel** — they state
            what Closient is and is not for this product, and the hosted product
            page renders them for the same reason.
          items:
            type: string
          title: Disclaimers
          type: array
        pip_url:
          description: Canonical hosted product page for this GTIN.
          title: Pip Url
          type: string
      required:
        - gtin
        - disclosure
        - recall
        - pip_url
      title: EmbedPanelOut
      type: object
    ErrorOut:
      description: |-
        RFC 9457 Problem Details response.

        All API errors are returned in this format with Content-Type:
        application/problem+json.
      examples:
        - detail: The requested resource was not found.
          error_code: not_found
          retryable: false
          status: 404
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Not Found
          type: https://closient.com/docs/errors/not_found
        - detail: Validation error.
          details:
            - loc:
                - body
                - name
              msg: Field required
              type: missing
          error_code: validation_error
          retryable: false
          status: 422
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Validation Error
          type: https://closient.com/docs/errors/validation_error
        - detail: Rate limit exceeded. Please try again later.
          error_code: rate_limited
          retry_after: 31
          retryable: true
          status: 429
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Rate Limited
          type: https://closient.com/docs/errors/rate_limited
      properties:
        type:
          description: URI reference identifying the error type.
          title: Type
          type: string
        title:
          description: Short human-readable summary of the error.
          title: Title
          type: string
        status:
          description: HTTP status code.
          title: Status
          type: integer
        detail:
          description: Human-readable explanation of this specific occurrence.
          title: Detail
          type: string
        error_code:
          description: Machine-readable error code (e.g. not_found, unauthorized).
          title: Error Code
          type: string
        retryable:
          default: false
          description: Whether retrying the same request can succeed.
          title: Retryable
          type: boolean
        timestamp:
          description: ISO 8601 timestamp of when the error occurred.
          title: Timestamp
          type: string
        retry_after:
          anyOf:
            - type: integer
            - type: 'null'
          description: Seconds to wait before retrying (when applicable).
          title: Retry After
        owner_action_required:
          anyOf:
            - type: boolean
            - type: 'null'
          description: Whether the error requires account owner intervention.
          title: Owner Action Required
        details:
          description: Additional context (validation errors, etc.).
          title: Details
      required:
        - type
        - title
        - status
        - detail
        - error_code
        - timestamp
      title: ErrorOut
      type: object
    EmbedDisclosureEnum:
      description: >-
        How much of a product record the embeddable PIP panel may carry
        (C-4300).


        Mirrors :class:`apps.products.services.embed_panel.EmbedDisclosure`.
        Kept

        in sync by
        ``test_public_embed_api.py::test_the_api_enum_mirrors_the_service_enum``

        — this module's mirrors are deliberately hand-rolled (see the module

        docstring) so member order is stable, and the cost of that choice is
        that

        drift has to be caught by a test rather than by construction.


        Part of the published contract rather than an implementation detail: an

        empty ``certifications`` list means "this product has none" on a
        ``full``

        response and "Closient will not assert them" on any other, and the field

        alone cannot tell those apart.
      enum:
        - full
        - suspended
        - unverified
        - age_restricted
      title: EmbedDisclosureEnum
      type: string
    EmbedRecallOut:
      description: Active-recall summary. Present at every disclosure level.
      examples:
        - count: 0
          headline: ''
          is_active: false
          severity_label: ''
        - count: 1
          headline: Undeclared milk in 12oz jars
          is_active: true
          severity_label: Serious Health Risk
      properties:
        is_active:
          description: True when this product has at least one open recall.
          title: Is Active
          type: boolean
        count:
          description: Number of open recalls.
          title: Count
          type: integer
        headline:
          default: ''
          description: Title of the most recent open recall. Empty when none is open.
          title: Headline
          type: string
        severity_label:
          default: ''
          description: >-
            Plain-language consumer severity for the most recent open recall,
            e.g. 'Serious Health Risk'.
          title: Severity Label
          type: string
      required:
        - is_active
        - count
      title: EmbedRecallOut
      type: object
    EmbedFactOut:
      description: One labelled row — an allergen, or a certification.
      examples:
        - detail: Legume allergen
          label: Peanuts
        - detail: Oregon Tilth
          label: USDA Organic
      properties:
        label:
          description: Display name, e.g. 'Peanuts' or 'USDA Organic'.
          title: Label
          type: string
        detail:
          default: ''
          description: >-
            Supporting text: trait description, or the issuing body. May be
            empty.
          title: Detail
          type: string
      required:
        - label
      title: EmbedFactOut
      type: object

````